Getting Data In

Universal Forwarder- Duplicate logs

Bill_B
Communicator

I have a Universal Forwarder on Win2008R2. The forwarder is reading Windows logs from a local file and forwarding to Splunk Enterprise. During setup, when prompted for what files to forward and the file path to read from, I selected "Security Logs" and "Forwarded Logs". Unfortunately the forwarder is now reading one event log and forwarding it as two logs; 1 labeled security logs and the other forwarded logs.

My Question is: What file do I need to change to get rid of either "Security Logs" or "Forwarded Logs"? (For example, I looked in $SPLUNK_HOME/etc/system/local/... inputs.conf and outputs.conf but I did not find the configuration in either location.)

Thank you.

0 Karma

Bill_B
Communicator

To solve this:

Modify file-
C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local\inputs.conf

All types of logs you don't want as a source should be edited to: "disable = 1"

The above file path is for a default install of Universal Forwarder on Windows2008R2.

0 Karma

lukejadamec
Super Champion

On the Splunk indexer, stop the remote inputs for the host.

Remote inputs are from wmi(configured on the indexer), local inputs are local(configured on the forwarder). They are both the same log file(s).

0 Karma

lukejadamec
Super Champion

I should have mentioned that you can confirm the duplicates are from using both local and remote sources by looking at the sources. WMI sources will contain 'WMI' in the name, and local ones won't.

0 Karma

lukejadamec
Super Champion

I think that depends on how they were configured. You will find them in the /etc/apps/someapp/local/wmi.conf file.

0 Karma

Bill_B
Communicator

What is the default location for remote inputs?
-Thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...